
wrongsecrets
Vulnerable app with examples showing how to not use secrets

Vulnerable app with examples showing how to not use secrets

Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…

Secure-by-default demo lab showing how container hardening (distroless images, non-root, read-only filesystem, runtime-injected secrets) can…

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…

a guard that blocks catastrophic agent actions

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.


Accompanying PowerShell Modules for DevSec Defense Presentation

Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks

ClusterImagePolicy demo for cve-2022-42889 text4shell

EU focused compliance MCP server

Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)